On one hand we have PCI-compliance, SSL encryption, and on the other hand we have a phone call (unecrypted, easily tappable anywhere along the thousands of miles of wire) where companies expect to call me and assume it's secure enough for me to 1) know that it's definitively them and 2) not have some support agent steal my credit card information/private information.
To which I reply “You called me. I don’t know that you are who you say you are. I’m not giving you anything.” And hang up. What moron thought this was a good idea?
One time my own bank scammed me into giving them my full seven digit SSN over the phone when they called me. And all they had to do was ask me for it!
The worst part was that I fell for it. Of course, no harm done, because it really was my bank, but what an idiot I was.
At least I knew better when the Windows Support people started calling me a year later!
You've seen off by one errors, this is twice as bad.
Apparently, every time I order medical supplies they call me to tell me that they've sent a Very Important Letter, but they can't say what it is. When it arrives the next day, it informs me that they've approved my request for the supplies, which by this point have already arrived a week and a half ago.
It's gotten to the point where the calls now go like this:
Them: Hi, this is [insurance company], can I have your date of birth please?
Me: Is this about the letter you've sent?
Them: ...Yes?
Me: OK, I'll keep an eye out.
Them: Erm... right. Have a nice day!
I have no idea what the moral of this story is.Even if it had been a fraudulent call, they weren't asking for anything (so I didn't have to bother verifying it was legitimate), and even if they got the wrong person there is limited damage they could do.
Also, at some point, it becomes infeasible enough (that someone would have redirected my mail, hijacked my phone number or managed to change it with the bank, triggered a call from my bank, and managed to line them all up so I hadn't noticed there was a problem) and more trouble than it's worth to be worried about it happening.
You’re the fraud prevention department for chrissakes. Act like you’re preventing fraud, not participating.
it is designed to be as convoluted as possible to
a) increase billable hours
b) create loops hole big enough to drive a truck through that the $$$$$ lawyers can exploit for their clients
But like you said, it's all about screwing the system and I'm sure a judge would not understand any of these concepts regardless of how simple someone would make them.
Now that I'm older it worries me that it is very possible to go to court and be on the right side and have a judge and jury who cannot comprehend these basic concepts. I've had bosses who work in software / hardware industry not understand concepts, God forbid I ever have to defend myself in a public forum.
It's actually incredibly annoying, my rental contract was sent via this method, so I have to go to the post office to pick it up, despite the fact that I actually live closer to the real estate agents office.
Why they couldn't just email it to me, I'm not entirely sure.
Restricted Delivery
Specify the person who can sign for and receive your item. Must be purchased in combination with another extra service as follows: Certified Mail, COD, Insured Mail (over $500), Registered Mail, or Signature Confirmation.
Edit: Per Stamps.com [0], the USPS “may” require ID on delivery, but again, in my experience, I’ve never been asked once.
[0] https://stamps.custhelp.com/app/answers/detail/a_id/157/~/re...
From another perspective though - while not "secure against manipulation", at least postal mail has federal laws with serious punitive remedies, and investigators who seem to genuinely be committed to enforcing those laws and chasing the penalties.
Most things in the real world are not "4096 bit cryptographically secured, guaranteed unbreakable before the heat death of the universe", instead they're "secured by people with guns, courts, and jails who are society's deterrence against smashing fragile windows, picking flimsy locks, and fraudulently filling out paperwork".
It _mostly_ works.
And in some ways, the "fiction of security backed by laws with teeth" works _better_. I locked myself out of my apartment recently, and my friend with my spare keys was on a trip ~800km away. So I called a locksmith, who got through the two locks on my front door in ~90 seconds. I'm _very_ glad he could, even though the tool he used is easily available on AliExpress for ~$25...
Most door locks and deadbolts in the US will fall to rakes in a minute or less. I've found the Southord L-rake and Pagoda to be pretty effective. These can be had in basic versions without much of a handle from southord.com for $1.65. (A tension tool is also required; it's pretty much just a bent piece of steel).
I kinda knew "ordinary domestic locks" weren't very secure agains skilled lockpickers, and I don't know if there's some hidden technique required to use those things - but I was astounded and dismayed at how quickly my two different locks fell to such an easily available tool...
In short, standard pins in locks only have one place they're likely to stick when manipulated under tension: the shear line that allows the lock to open. Security pins have additional grooves machined into them that will make the pin stick at points that do not result in the lock opening. It's still possible to pick locks that have them, but it often needs to be done one pin at a time, which is usually slower and tends to require more skill.
There are some pretty incredible stories about the USPIS.
https://en.wikipedia.org/wiki/United_States_Postal_Inspectio...
I was downloading Postal Service mp3s from Kazaa and ended up downloading some USPS disciplinary reports on accident. I shared them with a friend because I thought they were funny, and he posted excerpts on a message board. From there it somehow got to the USPSIS who tracked down my friend’s cell phone #. I eventually agreed to meet, so the inspector flew out from DC and met us at a diner in Santa Cruz. He showed us his badge and went over how I ended up with the files. The whole thing was sort of bizarre, but he was pretty friendly and seemed more interested in figuring out how the files got out than throwing the book at me or my friend.
ACH is also laughably insecure, the only thing standing between it and total chaos is federal prison.
If you have a merchant account, you can take direct debits from and account using those numbers. Getting a merchant account underwritten for yourself can take less than a day, and the verification process isn’t all that robust.
Account numbers are essentially more valuable than credit card numbers. Except credit card numbers are at least supposed to be protected by a rather decent security standard. With ACH there is no such standard, you can handle account numbers any way you please, and many merchants do so very poorly. Also, the account number is written on checks that you literally hand out to people, which is pretty much the worst thing you could do with a credit card number.
Your anecdote is meaningless. Any individual can easily commit fraud with an account number, and if they put a small amount of effort into it, they could do it on a very large scale. There is no security standard that protects ACH data, only a short set of regulations that describe how committing fraud will send you directly to prison.
And governments!
In my neighborhood I routinely get mail that is meant for my neighbors, and they get mine. I don't know if it's a sorting problem at the central office or driver incompetence but regular postal mail is absolutely not reliable.
I've tried to get it fixed online, but so far no results.
Imagine how terrible GMail's spam filters would be if spammers paid Google for delivery... Oh wait, Google literally has a dedicated tab for that! For those that find it useful (and I don't doubt it is), imagine what the alternative would be for the spammers, you'd be 100% ignoring it by unsubscribing or filtering it as spam. Now that it's corralled off, you can look at it at your leisure, and Google can keep advertisers happy by offering them a non-zero chance you'll look at their spam.
I mean, ok so USPS is getting $5/mo for my address from a dozen companies. Can I just pay them that $5? Not today.
I'd be happy to open the discussion on opting out of the junk mail without going to a costly service like earth-class mail.
I'll give you my two big complaints:
1) The time delay. My Traveling Mailbox address is in the western half of the US. Mail has to be delivered to that address, then shipped cross country to North Carolina where their headquarters and mail scanner is. You can count on an additional 3 to 14 days after USPS thinks the mail has been delivered before a scan of it shows up in my email inbox. A couple years ago, this was much worse and less consistent; occasionally letters were 3 weeks late. However in the past 2 years or so, I've noticed the time delay has been much more consistent, centering around 3-5 business days. They maintain addresses all over the country, and there's probably only the scale and margin to maintain one scanning facility, so I don't know what TM could realistically do to address this problem. If I didn't need an address where I have it, I would have already moved my address to Sanford, NC, where their headquarters is.
2) Some banks don't like the address. Due to KYC laws, banks and financial institutions need a residential address for their clients. I'm homeless and don't have such an address, so this is difficult for me. Traveling Mailbox is nice in that they give you a street address, not a P.O. Box. To a casual glance, it looks like a normal street address, but if one researches the address online, one will find that it's a business. When I changed my address over to use my TM address as my home address, about half the financial institutions I worked with rejected the address as not being my residence and said they couldn't do business with me anymore. Some asked for a driver's license as proof of the address. I said no problem and faxed my driver's license (which has my TM address), but the institutions still closed my account without further explanation. I'm still a little salty about the hubris of the politicians who enacted the KYC laws, assuming that everybody conforms and has a permanent residential address.
Edit: It should be obvious that you could do this with physical mail too.
The problem I see is that the processing and bandwidth used by advertising are currently "as much as advertisers can get away with" and I think it's leading to a tragedy of the commons.
But I see no need to eliminate ads and free services either. There just needs to be a cap enforced on the resources used.
Once it's in my mailbox, what can I do, drop it on the ground? That's littering and a crime. Leave it in my mailbox? I tried that and the mailman eventually stuck a Post-It note on my box saying I wasn't allowed to do that.
So I'm in some sort of weird uncontracted relationship wherein I must ferry a bunch of paper from my box to the recycling bin.
I used to do that until the mailman decided I didn't live here anymore...twice.
Now I apparently don't have a mailing address though the only bill I could never successfully get converted to all electronic (not from lack of trying) is the power company which messes them up every so often getting their bills returned every month.
I tried this with a twist, I wrote "return to sender" on it. Mail(wo)man also said "you cannot do this."
I'm curious if there's a list of things like this that the USPS explicitly does not allow..
1. Open the envelope and look for a pre-franked reply envelope. If there is one, stuff the junk into that and post it. Extra revenue for the postal service.
2. If it is a really persistent and annoying sender, mutilate my address and post it. This should result in it being routed back to the sender but does impose extra work on the postal service.
Sadly, I think the USPS now refuses to deliver those, after a rash of people taping return envelopes to cinder blocks a few decades back.
Well, yes, but it's insecure in the same way that the average bank branch is insecure:
- you're not going to get away with a lot (important stuff is sent using something more secure than first-class mail)
- you're automatically committing a felony
- your crime will automatically be investigated by federal law enforcement, not just the local donut patrol
Of course, the penalties are pretty harsh, so most people don't bother.
Uh, I didn't get one of those a few years ago when I moved. After the move I mailed something to my old address to make sure it worked.